Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5525

Опубликовано: 10 апр. 2026
Источник: nvd
CVSS3: 6
CVSS3: 7.8
EPSS Низкий

Описание

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:notepad-plus-plus:notepad\+\+:8.9.3:*:*:*:*:*:*:*

EPSS

Процентиль: 6%
0.00166
Низкий

6 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 6
github
5 месяцев назад

A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).

EPSS

Процентиль: 6%
0.00166
Низкий

6 Medium

CVSS3

7.8 High

CVSS3

Дефекты

CWE-121